---
format: "aidr-story-markdown/v1"
id: "5f4de46e650c1f22cc3d1a0092abc11809a6667762a8d88b2ecb2e13d83052a6"
canonical_url: "https://aidr.today/5f4de46e?lang=en"
title: "Check Point Finds ChatGPT Sandbox Flaw Letting Attackers Steal Gmail Data Across Accounts"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-08T23:48:25.000Z"
category: "Infra"
topics: ["openai","safety","infra","security","sandbox","data-exfiltration"]
source_urls: ["https://huggingnews.com/cybersecurity/check-point-finds-chatgpt-sandbox-flaw-letting-attackers-steal-gmail-dat-4794753d","https://x.com/IntCyberDigest/status/2097460795621913062","https://x.com/The_Cyber_News/status/2097356001385279844","https://x.com/technobezz/status/2097386780001476737","https://x.com/TheHackersNews/status/2097329657897197650","https://x.com/ethereaglehq/status/2097366141932892550"]
summary: "A hidden prompt in ChatGPT could trigger the chatbot to hand over data from integrated services including Google Drive and Microsoft Teams through a covert communication channel. The vulnerability exploited a shared clipboard between the assistant's code-execution containers, allowing an attacker to hijack a session and steal messages or files while the user saw no unusual activity. Check Point Research identified the sandbox flaw in June 2026 and verified that the channel allowed the extraction of Gmail chat history and uploaded files across different accounts. OpenAI has since decommissioned the internal server that powered the vulnerability, confirming the security hole was closed before the findings were publicized."
---

# Check Point Finds ChatGPT Sandbox Flaw Letting Attackers Steal Gmail Data Across Accounts

> [Open the canonical story](<https://aidr.today/5f4de46e?lang=en>)

**Published:** 2026-09-08T23:48:25.000Z
**Category:** Infra
**Topics:** openai, safety, infra, security, sandbox, data\-exfiltration

## Summary

A hidden prompt in ChatGPT could trigger the chatbot to hand over data from integrated services including Google Drive and Microsoft Teams through a covert communication channel\. The vulnerability exploited a shared clipboard between the assistant's code\-execution containers, allowing an attacker to hijack a session and steal messages or files while the user saw no unusual activity\. Check Point Research identified the sandbox flaw in June 2026 and verified that the channel allowed the extraction of Gmail chat history and uploaded files across different accounts\. OpenAI has since decommissioned the internal server that powered the vulnerability, confirming the security hole was closed before the findings were publicized\.

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/check-point-finds-chatgpt-sandbox-flaw-letting-attackers-steal-gmail-dat-4794753d>)
- [Story source](<https://x.com/IntCyberDigest/status/2097460795621913062>)
- [Supporting source](<https://x.com/The_Cyber_News/status/2097356001385279844>)
- [Supporting source](<https://x.com/technobezz/status/2097386780001476737>)
- [Story source](<https://x.com/TheHackersNews/status/2097329657897197650>)
- [Supporting source](<https://x.com/ethereaglehq/status/2097366141932892550>)

